{"id":"UBUNTU-CVE-2021-44964","details":"Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.","modified":"2026-05-20T16:05:21.904210984Z","published":"2022-03-14T15:15:00Z","upstream":["CVE-2021-44964"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-44964"},{"type":"REPORT","url":"http://lua-users.org/lists/lua-l/2021-12/msg00030.html"},{"type":"REPORT","url":"http://lua-users.org/lists/lua-l/2021-12/msg00015.html"},{"type":"REPORT","url":"https://github.com/Lua-Project/lua-5.4.4-sandbox-escape-with-new-vulnerability"},{"type":"REPORT","url":"http://lua-users.org/lists/lua-l/2021-11/msg00186.html"},{"type":"REPORT","url":"http://lua-users.org/lists/lua-l/2021-12/msg00007.html"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-44964"}],"affected":[{"package":{"name":"lua5.2","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/lua5.2?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.2.2-1","5.2.2-2","5.2.2-3","5.2.3-1"],"ecosystem_specific":{"binaries":[{"binary_name":"liblua5.2-0","binary_version":"5.2.3-1"},{"binary_version":"5.2.3-1","binary_name":"lua5.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-44964.json"}},{"package":{"name":"lua50","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/lua50?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.0.3-7"],"ecosystem_specific":{"binaries":[{"binary_name":"liblua50","binary_version":"5.0.3-7"},{"binary_name":"liblualib50","binary_version":"5.0.3-7"},{"binary_version":"5.0.3-7","binary_name":"lua50"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-44964.json"}},{"package":{"name":"lua5.2","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/lua5.2?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.2.4-1","5.2.4-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"liblua5.2-0","binary_version":"5.2.4-1ubuntu1"},{"binary_name":"lua5.2","binary_version":"5.2.4-1ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-44964.json"}},{"package":{"name":"lua5.3","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/lua5.3?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.3.1-1","5.3.1-1ubuntu2","5.3.1-1ubuntu2.1"],"ecosystem_specific":{"binaries":[{"binary_name":"liblua5.3-0","binary_version":"5.3.1-1ubuntu2.1"},{"binary_version":"5.3.1-1ubuntu2.1","binary_name":"lua5.3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-44964.json"}},{"package":{"name":"lua50","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/lua50?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.0.3-8"],"ecosystem_specific":{"binaries":[{"binary_name":"liblua50","binary_version":"5.0.3-8"},{"binary_version":"5.0.3-8","binary_name":"liblualib50"},{"binary_name":"lua50","binary_version":"5.0.3-8"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-44964.json"}},{"package":{"name":"lua50","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/lua50?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.0.3-8build1"],"ecosystem_specific":{"binaries":[{"binary_version":"5.0.3-8build1","binary_name":"liblua50"},{"binary_name":"liblualib50","binary_version":"5.0.3-8build1"},{"binary_version":"5.0.3-8build1","binary_name":"lua50"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-44964.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}